Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -172,6 +172,12 @@ jobs:
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
trivyignores: .trivyignore
# The Node.js install (needed only for Prisma engine generation) ships a
# bundled npm whose vendored node_modules carry their own tar,
# brace-expansion, etc. The app is built and run entirely with Bun and
# npm is never invoked, so skip that tree instead of chasing each new
# npm-vendored CVE in .trivyignore.
skip-dirs: 'usr/lib/node_modules/npm'
version: 'v0.69.3'
scanners: 'vuln,secret,misconfig'

Expand Down Expand Up @@ -291,6 +297,8 @@ jobs:
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
trivyignores: .trivyignore
# See note above: skip the base image's bundled npm (Bun runs the app).
skip-dirs: 'usr/lib/node_modules/npm'
version: 'v0.69.3'
scanners: 'vuln,secret,misconfig'

Expand Down
25 changes: 25 additions & 0 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ CVE-2026-42499 # net/mail: consumePhrase DoS (esbuild, lefthook)
CVE-2026-27145 # crypto/x509 DoS via excessive DNS name processing (esbuild, lefthook)
CVE-2026-39822 # os.Root symlink following directory traversal (esbuild, lefthook)
CVE-2026-42504 # mime: DoS via maliciously-crafted MIME header (esbuild, lefthook)
CVE-2026-56852 # golang.org/x/text: norm.Iter infinite loop (lefthook dev binary; latest 1.13.6, not shipped in app)

# Already remediated - suppresses stale-scan artifacts
# undici is pinned to 7.28.0 via package.json "overrides" (a listed fixed
Expand All @@ -62,3 +63,27 @@ CVE-2026-12151 # undici: WebSocket unbounded-memory DoS - fixed, on 7.28.0
CVE-2026-35209 # defu: prototype pollution (vulnerable code path unreachable in this project)
CVE-2026-4800 # lodash/lodash-es: prototype pollution (vulnerable code path unreachable in this project)

# Deferred to a dedicated OpenTelemetry upgrade
# @opentelemetry/propagator-jaeger is pulled transitively by
# @opentelemetry/sdk-trace-node@1.30.1 but is never used (the app configures the
# OTLP-HTTP exporter, not Jaeger propagation, and it is not imported anywhere in
# src/). The fix requires bumping the whole OTEL stack to 2.x, which is a
# separate upgrade. Remove this once OTEL is on 2.x.
CVE-2026-59892 # @opentelemetry/propagator-jaeger: DoS via malformed HTTP header decoding (unused, needs OTEL 2.x)

# Bundled npm CLI in the Node.js toolchain (image scan only, not app deps)
# The Dockerfile installs Node.js (needed for Prisma engine generation); the
# Node.js distribution ships a bundled npm whose vendored node_modules carry
# their own copies of tar and brace-expansion. The app is built and run entirely
# with Bun - bun.lock resolves brace-expansion to 5.0.9 and pulls in no tar at
# all - and npm is never invoked at build or runtime (the container CMD runs
# `bunx prisma migrate deploy && bun ./build/index.js`). The image scans skip the
# usr/lib/node_modules/npm tree via `skip-dirs`; these entries are a belt-and-
# suspenders fallback for the known npm-vendored CVEs. Not reachable in the app.
CVE-2026-59873 # tar (CRITICAL, gzip bomb): vendored in the base image's bundled npm, not the app
CVE-2026-59874 # tar: vendored in the base image's bundled npm, not the app
CVE-2026-13149 # brace-expansion: vendored in the base image's bundled npm (the app is on 5.0.9)
CVE-2026-14257 # brace-expansion: vendored in the base image's bundled npm (the app is on 5.0.9)
CVE-2026-69152 # brace-expansion: vendored in the base image's bundled npm (the app is on 5.0.9)
CVE-2026-69192 # ip-address: vendored in the base image's bundled npm (via npm's socks-proxy-agent), not an app dep

37 changes: 22 additions & 15 deletions bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

19 changes: 19 additions & 0 deletions messages/de.json
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,9 @@
"administration": "Administration",
"administrationConferenceSelection": "Wähle die Konferenz aus, die du verwalten möchtest. Wenn die Konferenz nicht angezeigt wird, lade die Seite neu oder wende dich an eine*n Administrator*in.",
"administrator": "Administrator*in",
"adoptedResolutions": "Verabschiedete Resolutionen",
"adoptedResolutionsDescription": "Lade hier die verabschiedeten Resolutionen hoch. Teilnehmende können sie nach dem Ende der Konferenz auf dem Abschlussbildschirm herunterladen.",
"adoptedResolutionsDownloadDescription": "Lade die auf der Konferenz verabschiedeten Resolutionen herunter.",
"after": "Nachher",
"agendaItemDetails": "Themendetails",
"agendaItemHasPapers": "Zu diesem Thema sind {count} Paper verknüpft. Diese werden ebenfalls gelöscht.",
Expand Down Expand Up @@ -1225,11 +1228,17 @@
"resolutionAddSibling": "Weitere hinzufügen",
"resolutionAddSubClause": "Unterklausel hinzufügen",
"resolutionAuthoringDelegation": "VERFASSENDE DELEGATION:",
"resolutionColumnActions": "Aktionen",
"resolutionColumnCommittee": "Gremium",
"resolutionColumnTitle": "Titel",
"resolutionCommittee": "Gremium",
"resolutionContinuationPlaceholder": "Fortsetzungstext...",
"resolutionDeleteBlock": "Text entfernen",
"resolutionDeleteClause": "Löschen",
"resolutionDeleteConfirm": "Möchtest du die Resolution „{title}“ wirklich löschen?",
"resolutionDeleteTitle": "Resolution löschen",
"resolutionDisclaimer": "Dieses Dokument ist im Rahmen einer Simulation bei {conferenceName} entstanden und spiegelt weder die Meinung der Teilnehmenden noch die der Veranstalter*innen oder des Vereins wider. Es ist kein Dokument der Vereinten Nationen.",
"resolutionDownload": "Herunterladen",
"resolutionEdit": "Bearbeiten",
"resolutionEditor": "Resolutions-Editor",
"resolutionEditorNotYetAvailable": "Der Resolutions-Editor und damit für dich die Möglichkeit, Arbeitspapiere einzureichen, stehen leider noch nicht zur Verfügung. Du wirst informiert, sobald du Arbeitspapiere einreichen kannst. Positionspapiere hingegen kannst du schon einreichen!",
Expand Down Expand Up @@ -1259,9 +1268,11 @@
"resolutionImportTipsPreamble3": "Du kannst Text direkt aus Word, Google Docs oder anderen Quellen einfügen",
"resolutionImportTipsTitle": "Tipps für beste Ergebnisse",
"resolutionIndent": "Einrücken",
"resolutionListEmpty": "Es wurden noch keine Resolutionen hochgeladen.",
"resolutionMoveDown": "Runter",
"resolutionMoveUp": "Hoch",
"resolutionNoClausesYet": "Noch keine Absätze. Füge Präambel- oder operative Absätze hinzu, um die Vorschau zu sehen.",
"resolutionNoCommittee": "Kein Gremium",
"resolutionNoOperativeClauses": "Noch keine operativen Absätze vorhanden.",
"resolutionNoPreambleClauses": "Noch kein Präambelabsatz vorhanden.",
"resolutionOperativeClauses": "Operative Absätze",
Expand All @@ -1278,6 +1289,14 @@
"resolutionTopic": "THEMA:",
"resolutionUnitedNations": "Vereinte Nationen",
"resolutionUnknownPhrase": "Unbekannter Operator",
"resolutionUploadCommitteeLabel": "Einem Gremium zuordnen (optional)",
"resolutionUploadError": "Die Resolutionen konnten nicht hochgeladen werden.",
"resolutionUploadLabel": "Resolutionen hochladen (PDF)",
"resolutionUploadNoFiles": "Bitte wähle mindestens eine Datei zum Hochladen aus.",
"resolutionUploadOnlyPdf": "Als Resolutionen können nur PDF-Dateien hochgeladen werden.",
"resolutionUploadSuccess": "Resolutionen hochgeladen.",
"resolutionUploadTooLarge": "Jede Resolutionsdatei darf höchstens 10 MB groß sein.",
"resolutionUploading": "Wird hochgeladen…",
"results": "Ergebnisse",
"review": "Überprüfen",
"reviewAddedSuccessfully": "Deine Bewertung wurde erfolgreich gespeichert.",
Expand Down
Loading
Loading